Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.9.
Published: 2026-05-27
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in RealMag777 Active Products Tables for WooCommerce is an improper neutralization of special elements in an SQL command, classified under CWE‑89. Attackers can inject malicious SQL through unsanitized input, which can lead to arbitrary data retrieval, modification, or deletion from the database. Because the injection is blind, attackers may need to infer information through timing or error responses, but still gain significant control over database contents.

Affected Systems

Any WordPress site running the Active Products Tables for WooCommerce plugin at versions n/a through 1.0.9 is affected. The vulnerability applies to all installations using those plugin versions, regardless of other site configuration.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity, though the EPSS score is not available, limiting precise exploitation probability estimates. The lack of a KEV listing suggests no known widespread exploitation to date, but the high CVSS and nature of the flaw mean attackers could potentially craft an exploit if they can reach the vulnerable input. The attack vector is likely remote, via web requests to endpoints handled by the plugin, and does not require local privileges. The flaw can be leveraged without initial authentication in many cases, enabling unauthorized data exposure or modification.

Generated by OpenCVE AI on May 27, 2026 at 11:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Active Products Tables for WooCommerce plugin to a version newer than 1.0.9, ensuring the latest security fixes are applied.
  • If an upgrade is not possible, disable or uninstall the plugin to eliminate the vulnerable code path.
  • Apply proper input validation and repository-safe parameterization on any custom database interactions to reduce the risk of similar injection flaws in custom modules.

Generated by OpenCVE AI on May 27, 2026 at 11:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Realmag777
Realmag777 active Products Tables For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Realmag777
Realmag777 active Products Tables For Woocommerce
Wordpress
Wordpress wordpress

Wed, 27 May 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.9.
Title WordPress Active Products Tables for WooCommerce plugin <= 1.0.9 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Realmag777 Active Products Tables For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-27T10:47:15.749Z

Reserved: 2026-04-29T09:05:44.122Z

Link: CVE-2026-42761

cve-icon Vulnrichment

Updated: 2026-05-27T10:47:10.340Z

cve-icon NVD

Status : Received

Published: 2026-05-27T11:16:22.763

Modified: 2026-05-27T11:16:22.763

Link: CVE-2026-42761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T11:45:15Z

Weaknesses